FREE MEMBERSHIP - Create your personalized Bitpipe Service!  Members: Sign in 
Search Bitpipe: 
  Search Help
CSI for the CISO
sponsored by Information Security Magazine
Posted:  06 Sep 2007
Published:  01 Sep 2007
Format:  HTML
Length:  10  Page(s)
Type:  Journal Article

ABSTRACT:

From all indications, something bad had happened. After installing an intrusion prevention system, the security team at UW Medicine spotted several machines trying to communicate with an IRC botnet server in France. Cindy Jenkins, a security engineer and computer forensics expert at the medical and research organization, immediately went on a hunt for clues behind the suspicious activity.

Hours spent combing through images of the hard drives from the infected PCs turned up the attackers' tools: an IRC bot, a rootkit and an FTP server. Passive network scanning detected more compromised systems. To save time, Jenkins made hash sets--digital fingerprints--of the malware so she could look just for the hash sets when inspecting additional images. She determined the machines were infected 18 to 24 months earlier--before the IPS and other security measures were installed.
 
View This Now
 
AUTHOR: 

Marcia Savage
Features Editor, Information Security


BROWSE RELATED RESOURCES:
Computer Forensics | Cybersecurity | Hackers | Industrial Espionage | Internal Threats | Intrusion Detection
View All Resources sponsored by Information Security Magazine

Home | About Us | Contact Us | Advertise with Us | Partner with Us | Site Index
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines

Definitions: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z Other   TechTarget - The Most Targeted IT Media
TechTarget Corporate Web Site  |   Media Kits  |   Site Map




All Rights Reserved, Copyright 2000 - 2007, TechTarget | Read our Privacy Statement